Armored Likho is a previously undocumented threat actor also associated with the name Eagle Werewolf. The group has been linked to active campaigns in 2026 that combine cyber-espionage against organizations with financially motivated activity against individuals. Confirmed targeting includes government entities, electric power organizations, IT companies, educational institutions, major corporations, and private users, with victims observed in Russia, Kazakhstan, and Brazil. Reporting also describes a campaign focused broadly on organizations and individuals in Russia, especially public-sector, IT, and education targets. Armored Likho relies heavily on spear-phishing and social-engineering lures, including themes related to official notices, social programs, humanitarian aid, and charitable assistance. Observed delivery chains have used malicious archives, executable droppers, and Windows shortcut files, including abuse of CVE-2025-9491, followed by obfuscated PowerShell and staged payload retrieval. The actor has shown signs of using AI-assisted or AI-generated first-stage loader code to vary tooling and complicate attribution. The group’s malware ecosystem includes BusySnake Stealer, AquilaRAT, Go2Tunnel, and the newer Rust-based Still Toolkit. BusySnake is a Python-based infostealer and backdoor framework used for credential theft, browser data theft, clipboard monitoring, screenshot capture, document collection, Telegram data theft, cryptocurrency-related theft, and remote operator access. It supports persistence through scheduled tasks, command execution, reverse SSH tunneling, and in newer variants in-memory execution of arbitrary Python scripts. BusySnake has also been used to deploy or interact with remote-access tooling and to maintain long-term access on compromised hosts. Still Toolkit reflects a more mature espionage capability set. Its Still Sync component steals Telegram Desktop session data and abuses authenticated sessions to collect account details, chats, groups, channels, contacts, and media through the Telegram API. Its Still Audio component performs covert microphone surveillance using voice-activity-triggered recording and exfiltrates captured audio. Both components are written in Rust and share architectural and cryptographic traits with earlier Armored Likho tooling, including overlaps with AquilaRAT. Researchers have linked these campaigns to Armored Likho through shared encryption methods, similar dropper architecture, matching host-identification logic, infrastructure patterns, and comparable tasking and persistence mechanisms. Observed tradecraft includes initial access, credential theft, session hijacking through theft of Telegram session artifacts, persistence, defense evasion through obfuscation and staged decryption, process injection in some delivery chains, exfiltration, and post-exploitation remote access. The actor appears focused on long-term intelligence collection in sensitive environments while also monetizing access or stolen data from individual victims. No specific state attribution is established with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
89 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a new cyber-espionage campaign using a fake charity-aid application as an initial infection vector, deploying the new Still Toolkit to steal Telegram Desktop session data and perform covert microphone-based audio surveillance for long-term intelligence collection.
Conducting a cyber-espionage campaign using a fake donation application to infect targets in Russia with the Rust-based Still Toolkit, enabling Telegram session theft, chat and file collection, and microphone surveillance.
Conducting a cyber-espionage campaign in Russia using fake donation-themed apps as droppers and a Rust-based toolkit to steal Telegram session data, collect chats/media, and perform covert audio surveillance.
Cyber-espionage campaign targeting private users and organizations in Russia using fake charity-themed applications as droppers and a new Rust-based Still Toolkit for Telegram session theft, Telegram data collection, and covert audio surveillance.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.